★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-5715.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Forums 9/17/2002 15:59

Patches Shouldn't Be Our Problem

Published By: NetworkComputing
Posted By: Adam Chalemian
9/17/2002

Back in the day, patches were used to cover holes in your jeans, not in commercial software. That's not to say software didn't include "undocumented features." But the severity of defects was nowhere near the level it is today, and we could afford to postpone fixes until the rollout of a subsequent software release.

Today, patches are not only commonplace, they're expected. And not just by customers, but by vendors. When Microsoft released Windows 2000, it did so knowing that the code stream contained thousands of defects. SP1 alone fixed more than 600 of these defects (see List of Bugs Fixed in Windows 2000 Service Pack 1.") Certainly some of them were minor, but it makes you wonder how many resulted in the rampant spread of Code Red, Nimda and other viruses.

Patch management today is a full-time job. You must keep track of all the patches available and micromanage them to ensure that the changes applied through installing a patch do not adversely affect production software. Companies need a mirror of their production environment simply as a test bed for the patch o' the week. Organizations need a tracking system to ensure they know which patch was installed when and on what machines. And the poor people managing it all need a vacation.


Click here to go to this article.

Chroot Jails Made Easy with the Jail Chroot ProjectRegister
Oct 11

Sendmail Trojan Looks Familiar
Oct 11

Digital Rights Management Issues In Real-Time and Safety/Mission Critical Systems
Oct 11

Clues, Vandalism, Litter Sendmail Trojan Trail
Oct 11

Snort 2.0 - Detection Revisited
Oct 11

Security Tops List of Reasons Not to Deploy Web Services
Oct 11

Is Linux Really More Secure Than Windows?
Oct 11

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000